Vulnerability Reportrust:1.94.0-alpine3.21

rust:1.94.0-alpine3.21
digestsha256:2ff5a7235f7b13b05b8a23c3c92737ad7adea11bf68ab5116b0e52991410c721

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. The image does contain 3 exposed-surface and 15 post-exploit findings, but their maximum severities (4.67 and 3.0) are low and none reach the thresholds that would require remediation. No CVE IDs appear in the provided top-finding data, so there are no specific known vulnerabilities to track. As an official, digest-pinned image with a perfect trust score, it provides a reliable foundation for building production images. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

20 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl-dev
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-31789LOW3
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28388LOW2.7
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28387LOW2.48
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
libssl3
3.3.6-r0
fixed in 3.3.7-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl
1.2.5-r9
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40200LOW2.39
musl-dev
1.2.5-r9
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22184LOW2.39
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW2.12
libcrypto3
3.3.6-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-31790LOW2.12
libssl3
3.3.6-r0
fixed in 3.3.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-40200NONE0
musl-utils
1.2.5-r9
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r9
fixed in 1.2.5-r10
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.